Friday, November 11, 2011

Modifier

Modifier

Modifier

Access Modifiers

Access modifiers are keywords used to specify the declared accessibility of types and type members. The four access modifiers are discussed in the table below:
Access ModifierMeaning
publicpublic is an access modifier for types and type members. This is the most permissive access level as there are no restrictions on accessing a public type or type member.
internalinternal is an access modifier for types and type members. internal members are accessible only within file of the same assembly. It is an error to reference an internal type or internal type member outside the assembly within which it was declared.

A common use of internal access is in component-based development because it enables a group of components to interact in a private matter without being exposed to the outer world. For example, a Data Access Layer could have several classes with internal members that are only used by the DAL.
protectedprotected is an access modifier for type members only. A protected member is only accessible within the body of the containing type and from within any classes derived from the containing type.
privateprivate is an access modifier for type members only. private access is the least accessible and such members are only accessible within the body of the containing type.
Note that nested types within the same containing body can also access those private members.

Accessibility Levels

The four access modifiers listed above result in five accessibility levels shown below. Note how certain accessibility levels are not permitted depending on the context in which an access modifiers was used:
Accessibility LevelMeaningApplies To NamespacesApplies To TypesApplies To Type Members
publicAccess is not restricted.YesYesYes
internalAccess is limited to the current assembly (project).NoYesYes
protectedAccess is limited to the containing class, and classes derived from the containing classNoNoYes
internal protectedAccess is limited to the current assembly (project), the containing class, and classes derived from the containing classNoNoYes
privateAccess is limited to the containing type.NoNoYes
The following table illustrates accessibility levels for namespaces, types, and type members. Note that namespace elements (i.e., classes, structs, interfaces and enum) can only have public or internaldeclared accessibility. Access modifiers private, protected,  and protected internal are not allowed on namespace members. 
ContextDefault AccessibilityAllowed Declared AccessibilityDefault Member AccessibilityAllowed Declared Accessibility On Members
namespacepublicNoneInternalpublic
internal
classinternal (if top level)public
internal
privatepublic
protected
internal
internal protected
private
interfaceinternal (if top level)public
internal
publicNone
structinternal (if top level)public
internal
privatepublic
internal
private
enuminternal (if top level)public
internal
pubicNone

Friday, October 14, 2011

diff bet having and where clause

Where clause does not work with aggregate wher having clause work.

Aggregate - sum ,max ,min ,Avg function

Solution Second



Where Clause:
1.Where Clause can be used other than Select statement also .
2.Where applies to each and single row .
3.In where clause the data that fetched from memory according to condition .
4.Where is used before GROUP BY clause .
Ex:Using Condition for the data in the memory.

Having Clause:
1.Having is used only with the SELECT statement.
2.Having applies to summarized rows (summarized with GROUP BY)
3.In having the completed data firstly fetched and then separated according to condition.
4.HAVING clause is used to impose condition on GROUP Function and is used after GROUP BY clause in the query
Ex: when using the avg function and then filter the data like ava(Sales)>0

Friday, September 30, 2011

How can you prevent a cookie from cross side script attacks?

Use HttpOnly property of the cookie when it is created.
It prevents the cookie from being accessible through Javascript.

ex:
HttpCookie h=new HttpCookie("userinfo");
h.HttpOnly=true;
h.Value="dd";
h.Expires=DateTime.Now.AddMinutes(3);
Response.Cookies.Add(h);

dynamic sql queries

Create PROCEDURE usp_demo (@TableName varchar(90),@ID varchar(90),@FName
varchar(90),@LName varchar(90),@PNum Varchar(90), @Email Varchar(90))
as
BEGIN
declare @SQL nvarchar(1000)
SELECT @SQL = 'Create Table ' + @TableName + ' ('SELECT @SQL = @SQL +'' +@ID+
' int NOT NULL Primary Key,' +@FName+ ' VarChar(10),' +@LName+ ' Varchar(90),'
+@PNum+ ' Varchar(90),' +@Email+ ' Varchar(90))'
SET @SQL = @SQL
EXECUTE SP_EXECUTESQL @SQL
END

identify hacking

ALTER PROCEDURE sp_IsValidLogon
@UserName varchar(16),
@Password varchar(16)
As
if exists(Select * From User_Table
Where UserName = @UserName
And
Password = @Password
And
Active = 1)
begin
return(1)
end
else
begin
INSERT INTO FailedLogons(UserName, Password)
values(@UserName, @Password)

declare @totalFails int
Select @totalFails = Count(*) From FailedLogons
Where UserName = @UserName
And dtFailed > GetDate()-1
if (@totalFails > 5)
UPDATE User_Table Set Active = 0
Where UserName = @UserName
return(0)
end
Go



Now, let's take a closer look at what I was doing. First thing, check to see if the
username and password exist on the same row, and that that user is active, if so, login is fine, return 1 to the
user and exit the procedure. If the login is not ok though, we want to log it. The first
thing the procedure does is insert the record into the 'FailedLogons' table.
Next we declare a variable to hold the number of failed logons for that same day. Next we
assign that value by using a sql statement to retrieve the number of records for that username,
within the same day. If that number is greater than 5, it's likely someone is trying to
hack that account so the the username will be disabled by setting the active flag in the
'User_Table' to 0. Finally, return 0 letting the calling code (ASP) know that
the login was unsuccessful. To accomplish this same task using only ASP, you would have
needed to make 4 database calls. The way we just did it it is still only one database call,
plus the fact that all that functionality we added at the end was in the stored procedure,
we didn't have to touch the ASP code at all!


Note about 'begin/end': When using an 'If' statement in a stored procedure, as long
as you keep the conditional code to one line you won't need a 'begin' or
'end' statement.

Note about 'begin/end': When using an 'If' statement in a stored procedure, as long
as you keep the conditional code to one line you won't need a 'begin' or
'end' statement. Example:


if (@myvar=1)
return(1)
else
return(2)



However, if you need more than one line, it is required that you use begin
and end. Example:


if (@myvar=1)
begin
do this.....
and this.....
return(1)
end
else
begin
do this....
return(2)
end